[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4va7CDv6q1wwJx3Hk9l_YC_E3rvqvx-RbdLgSdHPTXg":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"c858c070-71e5-4a88-9a9e-1e8378d45a1a","Critical Flaws Discovered in Belgian eID Software Used by 2 Million People","critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people-4f7981","The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.","Security researcher James Arnott discovered severe vulnerabilities in Belgium's Connective digital identity system, affecting over 2 million users, including major banks and government agencies. The flaws allowed malicious websites to potentially read eID and payment card details, trick users into revealing PINs for phishing, and forge legally binding electronic signatures. A separate remote code execution vulnerability could also allow attackers to run arbitrary code on a user's machine.","Critical flaws in Belgian eID software could expose user data and allow forged signatures.","DEF CON — A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures. James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission. According to Arnott, a malicious website could silently read connected electronic ID (eID) and payment card details. Furthermore, attackers could trick users into revealing their eID PIN by triggering official-looking authentication pop-ups. Because the software allowed web pages to customize the text inside these dialog boxes without displaying the domain making the request, users had no way to verify whether a prompt was legitimate or a phishing attempt. When a user entered their PIN into a prompt, the application transmitted it back to the requesting webpage. An attacker could then use the PIN to generate unauthorized approval tokens to forge legally binding electronic signatures whenever the victim’s physical eID card was inserted into a card reader. The compromise of the eID system severely impacted the trust model of Belgium’s broader digital ecosystem, including government portals like CSAM.be and third-party identity providers like Itsme. Advertisement. Scroll to continue reading. While these service providers contained no flaws of their own, their reliance on eID signatures meant that an attacker with stolen signing capabilities could register or hijack digital identity accounts. In addition to identity theft, the researcher uncovered a remote code execution vulnerability that operated independently of whether an eID card was plugged in. By exploiting a flaw in how the application processed files on the local computer, a malicious website could force the software to execute attacker-controlled code at the user level. An attacker could execute this drive-by attack by tricking a user into downloading a file disguised as a standard document and visiting a webpage. Requiring no special permissions, the flaw also carried the risk of spreading like a self-propagating worm by hijacking user credentials to send malicious links to other potential victims. Nitro fully remediated the issues 146 days after the initial report and awarded a $200 bug bounty. The company deployed updates to block unauthorized origin requests and secure PIN handling, with final security enforcement completed in late July. No CVEs appear to have been assigned. Nitro has not responded to SecurityWeek’s request for comment. Arnott publicly disclosed the findings at DEF CON and released a blog post with additional technical details. Related: Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Snowflake Hacker Pleads Guilty in US CourtZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsMeta AI Hacked External Systems During Cybersecurity TestingHow a $50,000 Exploit Chain Turned Bixby Against Samsung Phones New Attack Methods Enable Malware to Hijack Passkey-Protected AccountsCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data Water Sector Cyberattacks Reportedly Hit at Least 12 StatesTP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Latest News Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataIn Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall StreetVishing Extortion Group UNC6671 Rebrands After Making MillionsTruck Brake Controller’s Safety Recall Doubled as Hidden Security FixBlack Hat USA 2026 – Summary of Vendor Announcements (Part 4)Microsoft, Apple Release Fresh Security Updates3.8 Million Impacted by Unlimited Technology Systems Data BreachCritical Vulnerabilities Patched With Chrome 151 Update Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fcritical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002Feid-electronic-signature-e-signing.jpeg","2026-08-10T04:44:32+00:00","2026-08-10T06:00:12.579175+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"Connective","product",{"name":22,"type":23},"Nitro Software Belgium","vendor",{"name":25,"type":20},"eID",{"name":27,"type":20},"CSAM.be",{"name":29,"type":20},"Itsme",{"name":31,"type":32},"security researcher","threat_actor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]